Debian
Debian Dpkg: vulnerabilidades y CVE
Debian Dpkg tiene 15 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses2
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-88835 | Media (6.1) | 0.12% | — | 23 sept 2026 | BusyBox dpkg read_package_field() steps past a NUL terminator on malformed .deb packages, causing an out-of-bounds heap read. |
| CVE-2026-2219 | Alta (7.5) | 0.42% | — | 7 mar 2026 | It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, which may result in… |
| CVE-2025-6297 | Alta (8.2) | 0.38% | — | 1 jul 2025 | It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary directory, which is documented as being a safe operation even on untrusted data. This… |
| CVE-2022-1664 | Crítica (9.8) | 3.2% | — | 26 may 2022 | Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal vulnerability. When extracting untrusted source packages in v2 and… |
| CVE-2017-8283 | Crítica (9.8) | 4.6% | — | 26 abr 2017 | dpkg-source in dpkg 1.3.0 through 1.18.23 is able to use a non-GNU patch program and does not offer a protection mechanism for blank-indented diff hunks, which allows remote attackers to conduct directory traversal… |
| CVE-2015-0860 | Alta (7.5) | 5.0% | — | 3 dic 2015 | Off-by-one error in the extracthalf function in dpkg-deb/extract.c in the dpkg-deb component in Debian dpkg 1.16.x before 1.16.17 and 1.17.x before 1.17.26 allows remote attackers to execute arbitrary code via the… |
| CVE-2015-0840 | Media (4.3) | 1.8% | — | 13 abr 2015 | The dpkg-source command in Debian dpkg before 1.16.16 and 1.17.x before 1.17.25 allows remote attackers to bypass signature verification via a crafted Debian source control file (.dsc). |
| CVE-2014-8625 | Media (6.8) | 3.3% | — | 20 ene 2015 | Multiple format string vulnerabilities in the parse_error_msg function in parsehelp.c in dpkg before 1.17.22 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format… |
| CVE-2014-3227 | Media (6.4) | 1.8% | — | 30 may 2014 | dpkg 1.15.9, 1.16.x before 1.16.14, and 1.17.x before 1.17.9 expect the patch program to be compliant with a need for the "C-style encoded filenames" feature, but is supported in environments with noncompliant patch… |
| CVE-2014-3127 | Alta (7.1) | 2.1% | — | 14 may 2014 | dpkg 1.15.9 on Debian squeeze introduces support for the "C-style encoded filenames" feature without recognizing that the squeeze patch program lacks this feature, which triggers an interaction error that allows remote… |
| CVE-2014-0471 | Media (5) | 2.9% | — | 30 abr 2014 | Directory traversal vulnerability in the unpacking functionality in dpkg before 1.15.9, 1.16.x before 1.16.13, and 1.17.x before 1.17.8 allows remote attackers to write arbitrary files via a crafted source package,… |
| CVE-2011-0402 | Media (6.8) | 2.9% | — | 11 ene 2011 | dpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote attackers to modify arbitrary files via a symlink attack on unspecified files in the .pc directory. |
| CVE-2010-1679 | Media (6.8) | 3.1% | — | 11 ene 2011 | Directory traversal vulnerability in dpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote attackers to modify arbitrary files via directory traversal sequences in a patch for a source-format 3.0… |
| CVE-2004-2768 | Alta (7.2) | 0.41% | — | 8 jun 2010 | dpkg 1.9.21 does not properly reset the metadata of a file during replacement of the file in a package upgrade, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid file,… |
| CVE-2010-0396 | Media (5.8) | 2.0% | — | 15 mar 2010 | Directory traversal vulnerability in the dpkg-source component in dpkg before 1.14.29 allows remote attackers to modify arbitrary files via a crafted Debian source archive. |